CVE-2013-6746
Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0…
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/filenet case foundation · ibm/filenet content manager · ibm/filenet p8 business process manager
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/56500
- http://www.ibm.com/support/docview.wss?uid=swg21662360Vendor Advisory
- http://www.securityfocus.com/bid/65045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89862
- http://secunia.com/advisories/56500
- http://www.ibm.com/support/docview.wss?uid=swg21662360Vendor Advisory
- http://www.securityfocus.com/bid/65045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89862
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.